Re: Using Commercial SSL/TLS Certificate for debian.org Site

Paul Wise <[email protected]>
Newsgroups gmane.linux.debian.devel.www
Message-ID <CAKTje6FtugoDO1sz-e_DNsnjo4o=2XEi2Kv3BxvJUCc8gq-uCg@mail.gmail.com>
On Wed, Jun 19, 2019 at 12:51 PM Bagas Sanjaya wrote:

> Unlike LE, we (debian.org) have to create Certificate Signing Requests (CSR) which will be sent to those CA.

As a member of the Debian sysadmin team I can tell you that this is
never going to happen. Manually doing TLS is way too much work when
you have hundreds of subdomains and a terrible idea and we will never
go back to doing it.

> EV certificates can be useful for large organizations like Debian.

EV certificates are becoming less useful over time, they are probably
a waste of money now:

https://scotthelme.co.uk/are-ev-certificates-worth-the-paper-theyre-written-on/

> would commercial SSL/TLS make sense for debian.org website?

No.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.